Why do phishers waste their time with such obvious phishing scams when they can do so much better? One possible answer: They don’t have to do better. They send out so many emails that they only need a very low percentage of people to click. And people always do. In fact, if phishing emails became […]
Category: Cybersecurity
Posts about Cybersecurity by Professor Daniel J. Solove for his blog at TeachPrivacy, a privacy awareness and security training company.
Clearing Up the Fog of Cloud Service Agreements
Contracting with cloud service providers has long been a world shrouded in fog. Across various organizations, cloud service agreements (CSAs) are all over the place, and often many people entering into these contracts have no idea what provisions they should have to protect their data.
The Funniest Password Recovery Questions and Why Even These Don’t Work
A recent article in Wired argues that it is time to kill password recovery questions. Password recovery questions are those questions that you set up in case you forget your password. Common questions are: In what city were you born? What is your mother’s maiden name? Where did you go to high school?
Ransomware: A Cartoon to Brighten More Bad News
I have good news and bad news about ransomware. First, the good news — here’s a cartoon I created. I hope you enjoy it, because that’s the only good news i have. Now, for the bad news . . . The Bad News: Be Afraid, Very Afraid Everyone seems to be afraid of ransomware these […]
Passwords Cartoon – Security Awareness Training
Here’s a cartoon I created to illustrate the importance of security awareness training. I hope you find it amusing.
Ransomware Growing Out of Control
Security experts are sounding the alarm bell as ransomware attacks continue to increase rapidly since my last post on the subject.
Attorney Confidentiality, Cybersecurity, and the Cloud
There is a significant degree of confusion and lack of awareness about attorney confidentiality and cybersecurity obligations. This issue is especially acute when it comes to using the cloud to store privileged documents. A common myth is that storing privileged documents in the cloud is a breach of attorney-client confidentiality. In other instances, many attorneys […]
6 Great TV Series About Privacy and Security
In previous posts, I have listed some of my favorite novels and movies about privacy and security issues. I don’t want to leave out TV, as there are some great TV series too.
New Resource Page: How to Make Security Training Effective
I recently created a new resource page — How to Make Security Training Effective. The page contains my advice for how to make security training memorable and effective in changing behavior. Training the workforce is an essential way to protect data security, but not all training endeavors are successful. Poor training is akin to shouting […]
New Resource Page: Security Awareness Training FAQ
What laws require security awareness training? What topics do the laws require to be covered? What should be covered? How frequently should training be given? I recently created a new resource page — Security Awareness Training FAQ — to answer the above questions and more. I discuss various legal and industry requirements for security awareness […]